Jump to content

MikeC

Members
  • Posts

    2
  • Joined

  • Last visited

Reputation

0 Neutral

About MikeC

Personal Information

  • Occupation
    IT Security and Active Directory Architecture
  • Location
    San Diego
  1. I helped with a migration not too long ago and from the IT / Admin side, it was not too bad at all. The 365 system itself is quite reliable and mail delivery / receipt is fast, especially on mobile devices. Included FOSE filtering / gateway is nice. Plus the huge benefit of no longer having to maintain exchange servers and related gateways. From the end user side, sure there are "migration instructions" provided by MS, but we found the steps to be lacking and not entirely accurate. I would stronly suggest walking through a test migration scenario as a normal end user and writing out the exact steps to make a usable guide you can distribute. If users will only access 365 via OWA, then it's quite simple as the new 365 logon portal is very easy to access / use. I'm not sure about the MOSS portion as we've not looked at that piece of it much. Good luck! PS do not use the suggested Office 365 SPF reference of "outlook.com" provided by Microsoft (if you will be using SPF in your DNS). It will cause your SPF checks to fail on ourbound sent mail- MS set up the outlook.com SPF record with too many lookups in itself, they are aware of the issue but over a year now they still have not fixed it. I don't have it offhand, but use the old "BPOS" SPF record reference as that works fine. Should be findable in Google.
  2. Hello Boombah- I'm a longtime lurker and 1st time poster. I would like to suggest looking at Password Reset PRO from www.sysoptools.com - We run IT at a few EDU campuses and this web based self service tool works very well. We found out about it from another EDU IT shop that uses it. It is secure for extranet (public) access deployment, completely customizable (make your own look / feel), super easy to deploy, has provision for HA/DR, supports mobile device access (iphone, BB, WM, android) and any browser (IE, Safari, Opera, Chrome etc). It is enterprise class but has a very low price point. Sure you can use IISADMPWD but it is only marginally functional- e.g. it will not help with expired, lost or forgotten paswords or locked out accounts. For that you need a more robust solution. Unfortunately, most purchasable products of this type are not secure for extranet deployment and will have you do things like run the actual self service website process with domain admin privs, and it must be installed on a domain member server. Also there will be flaky features like a central admin (keys to the kingdom) page directly in the self service portal itself, and you'll probably have to run some sort of SQL or MySql database. All make for a very risky system to publish externally, and you do not want to open up a security hole in your extranet. You also want something extremely bulletproof and reliable! We literallty looked at 20 different solutions and the Password Reset PRO was the only one that passed all tests and criteria - For example, the web based portion resides on a non-domain IIS web server in a DMZ away from the internal domain, has no domain credentials, and you manage it just like any regular IIS website. There is an internal portion that has the credentials and it is installed separately from the web site safe inside the LAN. Very cool. We also like Hitachi's "Hitachi ID" but it was much more expensive and we did not need all of the SSO options for connecting various types of systems. Plus it still required running the self service site process with domain credentials. FOSE is also worth looking at and most EDUs can get it cheap, but the self service portion is not as flexible or feature rich as Reset PRO especially in a "BYOD" environment - which is actually very common these days. Anyway good luck and hope this helps.
×
×
  • Create New...